PatchSiren

Andrew CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Andrew CVE published 2026-04-08

CVE-2026-39701

CVE-2026-39701 is a Missing Authorization vulnerability in the ShopWP WordPress plugin. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM. It affects ShopWP versions from n/a through <= 5.2.4. The vulnerability is caused by a missing authorization check in the ShopWP plugin, allowing attackers to exploit incorrectly configured access control security levels. Users of the ShopWP WordPre [truncated]